CVE-2013-20001 describes a critical vulnerability in OpenZFS versions up to 2.0.3, where NFS shares configured with IPv6 address restrictions via the sharenfs feature fail to parse these addresses correctly, resulting in unrestricted access to the shared data. This vulnerability has a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low complexity and no user interaction, potentially leading to full confidentiality compromise. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for unauthorized data access remains a serious concern for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.3CPE matchmatch criteria | cpe:2.3:a:openzfs:openzfs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.